Cannot validate enc certificate

Document ID : KB000106077
Last Modified Date : 12/07/2018
Show Technical Document Details
Issue:
ENC Clients belonging to a known working ENC Server can sometimes fail if not configured with the exact FQDN of the ENC Server used in the ENC Server's Client Certificate
If the logs are checked, you may find an error message similar to "The target principal name is incorrect".
Environment:
any supported ENC environment
Cause:
100718-01:28:16.5937180L|007904|00000924|encclient |communicatorLib |communicatorLib     |000000|ERROR  | EncInitializeSecurityContext: The target principal name is incorrect.
Resolution:
ENC Client is likely pointing to an incorrect or invalid FQDN that does not match the FQDN specified in the Alternate Subject Name portion of the client certificate on the ENC Server.

Run a command like the following to correct the issue:

encutilcmd client -state enabled -server <proper ENC Server FQDN>

If the command runs successfully you will see the following after hitting enter:

INFO: Command completed successfully.

Now recycle ENC Client (CAF STOP ENC CLIENT / CAF START ENCCLIENT) and test.